CVE-2026-56142: JetBrains Hub

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible

Affected products

  • JetBrains Hub: from 2024.2.33606, before 2024.2.148429 (fixed in 2024.2.148429); from 2024.3.44799, before 2024.3.148430 (fixed in 2024.3.148430); from 2025.1.62455, before 2025.1.148120 (fixed in 2025.1.148120); from 2025.2.86069, before 2025.2.148048 (fixed in 2025.2.148048); from 2025.3.104432, before 2025.3.148033 (fixed in 2025.3.148033); from 2026.1.12024, before 2026.1.13757 (fixed in 2026.1.13757)

Published 2026-06-19. Last modified 2026-06-26.